Technique.View on attack.mitre.org
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts. Adversaries may also subsequently log off and/or perform a System Shutdown/Reboot to set malicious changes into place.
In Windows, Net utility, Set-LocalUser and Set-ADAccountPassword PowerShell cmdlets may be used by adversaries to modify user accounts. Accounts could also be disabled by Group Policy. In Linux, the passwd utility may be used to change passwords. On ESXi servers, accounts can be removed or modified via esxcli (`system account set`, `system account remove`).
Adversaries who use ransomware or similar attacks may first perform this and other Impact behaviors, such as Data Destruction and Defacement, in order to impede incident response/recovery before completing the Data Encrypted for Impact objective.
Rules on DetectionCode tagged with T1531.
| Rule | Level | Log source |
|---|---|---|
| AWS SAML Provider Deletion Activity | medium | aws / NULL |
| Azure Kubernetes Service Account Modified or Deleted | medium | azure / NULL |
| Google Cloud Service Account Disabled or Deleted | medium | gcp / NULL |
| Group Has Been Deleted Via Groupdel | medium | linux / process_creation |
| Okta User Account Locked Out | medium | okta / NULL |
| Remove Account From Domain Admin Group | medium | windows / ps_script |
| User Has Been Deleted Via Userdel | medium | linux / process_creation |
| AWS ElastiCache Security Group Modified or Deleted | low | aws / NULL |
| User Logoff Event | informational | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - User Account Deleted From Local Database | Anomaly | NULL | Cisco ASA Logs |
| Deleting Of Net Users | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Disabling Net User Account | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Excessive Usage Of Net App | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Account Access Removal via Logoff Exec | Anomaly | NULL | Sysmon EventID 1 |
| Windows Excessive Usage Of Net App | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Powershell Logoff User via Quser | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows User Deletion Via Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows User Disabled Via Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAkira | Akira deletes administrator accounts in victim networks prior to encryption. |
| GroupLAPSUS$ | LAPSUS$ has removed a targeted organization's global admin accounts to lock the organization out of all access. |
| Used by | Procedure example |
|---|---|
| MalwareDEADWOOD | DEADWOOD changes the password for local and domain users via |
| MalwareLockerGoga | LockerGoga has been observed changing account passwords and logging off current users. |
| MalwareMegaCortex | MegaCortex has changed user account passwords and logged users off the system. |
| MalwareMeteor | Meteor has the ability to change the password of local users on compromised hosts and can log off users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.